Описание
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.
Ссылки
- URL Repurposed
- Broken Link
- Broken LinkPatchVendor Advisory
- Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
- Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
- Issue TrackingPatchVendor Advisory
- URL Repurposed
- Broken Link
- Broken LinkPatchVendor Advisory
- Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
- Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
- Issue TrackingPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.4 (включая)
cpe:2.3:a:mozilla:mozilla:*:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:sco:openserver:5.0.7:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01149
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 9.8
debian
почти 22 года назад
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earl ...
CVSS3: 9.8
github
больше 3 лет назад
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.
EPSS
Процентиль: 78%
0.01149
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-502